Refresh an expired access token
Hard120 pts~45 min
- Token expiry
- Refresh tokens
Practice app · Acme REST API
A live REST + GraphQL API with auth, validation, pagination, rate limiting and an interactive request console.
Your starter code already declares BASE_URL — call the API relative to it.
Objective
Let an access token expire, detect TOKEN_EXPIRED, refresh it and retry successfully.
Your task
- 1POST BASE_URL + "/auth/token?ttl=1" with the admin fixture; keep access_token and refresh_token.
- 2Wait ~2 s, GET BASE_URL + "/auth/me" → assert 401 and error.code "TOKEN_EXPIRED".
- 3POST BASE_URL + "/auth/refresh" with { "refresh_token" } → assert 200 and a new access_token.
- 4Retry /auth/me with the new token → assert 200.
Acceptance criteria
- GET /auth/me returns 401 with the expired token
- POST /auth/refresh returns 200
- GET /auth/me returns 200 after refresh
- At least 3 assertions pass
Fixtures
- apiKey
- tqa_live_key_123
- basicUser
- admin
- basicPassword
- secret
- username
- qa@target.dev
- password
- Test@123
API testing · API Testing · Authentication